Skip to main content

Help us improve the Digital Marketplace - send your feedback

UNICARD LIMITED

Unicard Smart Ticketing Service

Solution for commercial ticketing and ENCTS concessionary management with smart ticketing. Includes a cloud-based Customer Management System (CMS), ITSO HOPS, cEMV Ticketing, AMS and Part11 Fulfilment, Account Based Ticketing, Payments, Customer Portal and App, Reporting, and Support. Delivered as cEMV deployment (tap-and-go ABT), HOPS deployment, HOPS migration or HOPS integration.

Features

  • Passenger Management, Ticket Management, Travel Management, and Cardholder Management
  • English National Concessionary Travel Scheme (ENCTS), Youth, Home to School
  • Commercial Travel Scheme Retail, Tap and Go, Account Based Ticketing
  • Full API access, data lake, and data source integration
  • Managed customer registration / managed customer support
  • Multi-token capable including ITSO, Barcode / QR ticketing, app, cEMV
  • Account Based Ticketing, Fare Capping, Settlement and Reconciliation
  • 24/7 support desk, debt recovery, fraud management
  • ITSO certified, PCI compliant, EMV for Transit approved
  • Hardware agnostic tap collection, payments orchestration, payments service processor

Benefits

  • Fully integrated service for cost reduction and management overhead reduction
  • Easy existing ITSO Migration / cEMV migration
  • Future-proofed including artificial intelligence, MaaS, Check-in-Check-out
  • Integrated payments processing, Account Based Ticketing, fares engine
  • Low training requirements, easy interface, increased contact centre efficiency
  • Solutions for Local Authorities, Transport Authorities, Private Operators, School Travel
  • Multi-operator configurations, ITSO terminal configuration, iSAM managed service
  • Supports transport ticketing, non-transport ticketing, leisure ticketing, parking, ferries, tolls
  • Customer Relationship Management, Invoicing management, Transport reporting
  • Integrated Data Lake, Data Warehouse, APIs, Reporting, and Monitoring

Pricing

  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at sales@unicard-uk.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

1 8 5 9 2 1 1 3 4 3 1 7 4 1 0

Contact

UNICARD LIMITED Alex Sbardella
Telephone: 01202850810
Email: sales@unicard-uk.com

About your service

Service categories

Applications

Production and operations

Service industry and public sector operations

  • Other
Multi cloud support
No

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
Existing HOPS, EMV Backoffice, EMV Middleoffice, CMS, Portals, Ticket Retail or Collection services, and Transport Information apps
Cloud deployment model
Hybrid cloud
Service constraints
Planned maintenance, bug fixes, and new feature releases are carried out on a schedule published in advance and agreed with the customer
System requirements
  • Access to administrative functions is restricted to whitelisted IPs
  • Server-to-server communications require a certificate to be installed
  • Service can be accessed in up-to-date web browsers

User support

Email or online ticketing support
Yes
Support response times
● Priority 1 Fault (Critical): Response within 1 business hour
● Priority 2 Fault (High): Response within 4 business hours
● Priority 3 Fault (Medium): Response within 6 business hours
● Priority 4 Fault (Low): Response within 8 business hours
● Service Request: Response within 8 business hours

Figures quoted for Silver tier support. Enhanced support packages with faster response times are available. Response times are the same at weekends/holidays if the appropriate add-on has been purchased.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Our system offers 98% uptime, 24/7/365 web service desk availability to raise tickets, telephone support 8am-6pm Monday-Friday excluding holidays, and a nominated support or account manager for each customer. This support level is included in the cost; further support levels are available as paid extras.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
We usually hold a single “train the trainers” session, lasting half a day, at the buyer’s offices for all managers using the system (up to 20 people), comprising a guided presentation and live demo, followed by Q&A, for each area of the system. The training is usually led by a Support Analyst for the system and the Account Manager. User documentation is also provided following the training session, including a knowledgebase. Follow-up training and revised documentation, for example after a major new update, can be arranged as part of the support agreement.
Specific questions that users have raised following training, that can’t be answered by the buyer’s trainers, can be submitted as support tickets.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
Data can be extracted through the system APIs or can be provided in an industry-standard ITSO export format.
End-of-contract process
We will facilitate a reasonable migration of data to a new provider in industry-standard export formats defined by Unicard. Custom export formats, extra integration support for the new provider, or project management of the overall migration are available at extra cost as per rate card.
Documentation accessibility standard
WCAG 2.2 A

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Some administrative functions are still functional but not optimised for use on mobile devices. Users will need to zoom/scroll to use all parts of the page and touch zones may not be optimised.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
The main service interface is provided through a web browser. A full API interface layer is also provided with WSDL and documentation.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
The system has undergone an audit for WCAG best practice but no specific testing with assistive technology has taken place.
API
Yes
What users can and can't do using the API
The majority of day-to-day management functionality and data access can be done using the API in a secure manner. API documentation is available under NDA to paying customers.
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • PDF
API sandbox or test environment
Yes
Customisation available
No

Scaling

Independence of resources
Services are hosted in an autoscaling AWS environment in accordance with AWS Well Architected Framework principles. Human resources are managed using a resource planning process.

Analytics

Service usage metrics
Yes
Metrics types
Users can access a range of standardised reports on the data contained within the system as well as monthly service performance reports for the system itself (e.g. uptime). Data can also be imported into an external business intelligence tool.
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
Physical access control, complying with SSAE-18 / ISAE 3402
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure

Data importing and exporting

Data export approach
Data can be exported through the system APIs. Some reporting data is available via email exports. Bulk and custom exports can be provided at extra cost.
Data export formats
  • CSV
  • Other
Other data export formats
  • SQL Database Extract with Schema
  • AWS Glue
Data import formats
  • CSV
  • Other
Other data import formats
  • SQL Database Extract with Schema
  • AWS Glue

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway

Availability and resilience

Guaranteed availability
We offer a 95% uptime guarantee. For each 1% of uptime under the 95% service level for any given month, a service credit of 0.2% of the contract value will be applied to the account. Extended availability up to 99.99% is available as a paid extra.
Approach to resilience
This information is sensitive, but we can make it available upon request.
Outage reporting
Users have access to a real-time service dashboard and are notified of major incidents via email alerts.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
Access restrictions in management interfaces and support channels
All users are required to have individual accounts, this ensures access to data is given based on job roles and security levels. The service team will at times require "superuser" access, however there are 2 separate accounts used to ensure that a superuser account is only used when required to minimalize risk. Only the service team can communicate with customers, access to the service desk from outside the support team is approved by the support manager, and these accounts can only read tickets and make internal comments. Access is removed on the day on an employee leaves.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
We operate a robust ISMS, governed by ISO27001 framework and security policies, which are reviewed and updated at least annually. Within the business there is a separation of duties between the information security officer and the data protection officer, providing an enhanced level of security governance. We operate a risk management committee, which meets every month to review any current or new risks. New starters are inducted in Unicards security policy and procedures and any changes to these are communicated to the wider company, with a link for them to access the changed policy.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
A secure configuration framework is part of our ISMS. We follow the AWS Well Architected Framework alongside tools such as AWS Config through continuous security scans to ensure that the solution remains secure. Any changes to the configuration, infrastructure, or application are only deployed following approval at an internal Change Advisory Board and are tracked via a Jira ticketing system throughout the lifespan. Unicard align our secure configuration practices with CIS Benchmarks, Cyber Essentials Plus, PCI DSS v4 and AWS Foundational Security Best Practices.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Risks are identified, assessed and impacted and mitigated in accordance with the requirements of PCI-DSS and ISO 27001:2013 and in cooperation with the buyer. We use Qualys for vulnerability scans to detect misconfigurations and continuous monitoring. Advanced Endpoint Protection (AEP) solutions, such as AWS GuardDuty, Microsoft Defender for Endpoint, and AWS Security Hub, are utilised to enhance detection and prevention capabilities. A Patch Management Standard enforces timely updates for software and systems in conjunction with AWS' O/S patching regime.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
We have a number of monitoring controls in place, from application level monitoring, through to infrastructure and network, as well as AWS tools. The firewalls and IDS system alert on any unusual network traffic or access attempts. We have automated log shipping, to allow server and system access to be protected and not deletable. Alerts are raised to the 24/7 support function and Unicard has a well structured emergency response team (ERT) that takes immediate control of any known or potential breaches.
Incident management type
Supplier-defined controls
Incident management approach
Processes are based on the ITIL Framework and ISO 20000 certification. Incidents can be raised by the internal monitoring and support teams as a MI ticket or incidents raised by customers via the Service Desk or by phone. The process is run by the Incident Manager, who is responsible for communication between the teams updating customers via email on a regular basis. Upon resolution a MIR report is provided by email containing the summary of the issue, timeline of events, a detailed root cause analysis, mitigation plan, and long term fix plan.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Supplier-defined process

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
Prospective customers can access a generic version of our Customer Management System loaded with a test data set for a reasonable time.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
LRQA
ISO/IEC 27001 accreditation date
Wednesday 2 July 2025
What the ISO/IEC 27001 doesn’t cover
N/A
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
LRQA
ISO 9001 accreditation date
Thursday 12 June 2025
What the ISO 9001 doesn’t cover
N/A
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
Yes
Who accredited the PCI DSS certification
Self-Assessment
PCI DSS accreditation date
Monday 14 April 2025
What the PCI DSS doesn’t cover
Any systems not processing PCI data are not PCI-DSS certified.
Cyber essentials
No
Cyber Essentials Alternative
None of the criteria
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
A8015596-df48-4f20-8cb5-13b08001f223
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Volunteering opportunities for staff
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Advertising of supply chain opportunities openly and to ensure they are accessible to a diverse range of businesses, including advertising all subcontracting opportunities on Contracts Finder

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at sales@unicard-uk.com. Tell them what format you need. It will help if you say what assistive technology you use.